This one is practical, not comforting. If you're trans in the United States right now, your medical paperwork isn't just paperwork — under an administration openly hostile to us, it's a map of who we are, held by people we didn't choose. You can't make the map vanish, but you can make it much harder to read. Here's how your data actually moves, and every opt-out worth your evening.
First: HIPAA is smaller than you think
HIPAA binds covered entities — your doctor, your pharmacy, your insurer. It does not bind most health apps, period-tracker-style tools, church prayer lists, your employer's wellness program, or the 47 advertising scripts embedded in your clinic's website. Once your data hops into an app or an ad network, it's in the open market. The FTC has fined companies (GoodRx, BetterHelp, Premom) for exactly this — after the fact, after the data already left. Enforcement is a mop, not a wall.
The five pipelines
1. Insurer claims & EOBs
Every billed visit becomes a claim with diagnosis codes — including gender dysphoria codes and HRT CPT codes. Then comes the EOB ("Explanation of Benefits"), mailed to the policyholder. If you're on a parent's or partner's plan, the EOB is how transitions get outed.
- Request "confidential communications" — federal regulation (45 CFR §164.522(b)) lets you tell your insurer to send sensitive EOBs somewhere safe (electronic only, alternate address). Say that exact phrase. Insurers hate it; it works.
- Ask which services appear on EOBs before consenting to billing codes — sometimes clinics can use less-specific codes for labs.
- If you can safely pay out-of-pocket through a compounding pharmacy or sliding-scale clinic, no claim exists. Know your state's laws first.
2. Patient portals & clinic websites
Clinic sites routinely embed Meta Pixel and Google Analytics — meaning clicking "Book Appointment" while logged into Facebook has literally transmitted appointment intent to advertisers (this is documented, litigated fact). Your portal itself is usually fine; the marketing pages aren't.
- Install uBlock Origin before touching any healthcare site. Watch the F12 Network tab — if booking a visit fires requests to facebook.com, that clinic is selling your intent.
- Use portals' internal messaging for anything sensitive, never SMS or email.
3. Apps & the broker economy
Any health app that's free is selling something. Prescription-reminder apps, pill trackers, pharmacy coupon cards — many monetize by shipping your med list to brokers like Acxiom, Epsilon, and Verisk/Infutor, who resell "health segments" to anyone paying.
- Prefer tools that are local-first (hi 👋) or open-source with no analytics SDKs.
- Coupon cards like GoodRx are marketing products: purchases flow through their systems and get shared. Pharmacies' own discount programs or cash pricing leave different trails.
4. Pharmacies & prescriptions
Controlled-substance monitoring exists state by state; ordinary prescriptions feed pharmacy chains' data warehouses. Chains have shared "customer insights" with brokers before. Loyalty accounts tie your legal name to every fill forever.
- If your chain account uses your deadname or old address, fix it — mismatched records create their own risk.
- Using one consistent pharmacy beats scattering fills across three; consistency looks boring, and boring is safe.
5. Courts, cops, and subpoenas
Records exist to be produced when legally compelled. What protects you here is mostly geography: many states with shield laws restrict disclosure of gender-affirming care records and refuse cooperation with out-of-state investigations; other states actively cooperate. If you live in or travel through a hostile state, minimize what crosses its servers: telehealth appointments route through company infrastructure somewhere — ask where.
The opt-out checklist
Do these once, tonight, in this order:
- Data brokers: submit opt-outs at Acxiom, Epsilon, and Verisk/Infutor. Then work through the master list at the Privacy Rights Clearinghouse. Re-check yearly — they repopulate.
- Ad tracking: opt out via NAI and DAA; reset your phone's advertising ID (iOS: Settings → Privacy → Tracking off; Android: Privacy → Ads → Delete advertising ID).
- Insurer: call the number on your card, request confidential communications, and ask for a list of who else received your disclosures — that's your HIPAA "accounting of disclosures" right.
- Portal hygiene: uBlock Origin everywhere; turn off portal marketing emails; never use social logins for health anything.
- Devices: strip health data out of cloud-synced notes/calendars; move logs to local-first storage. If an app offers "export," export and uninstall it.
- Signal for anything about your care you wouldn't want read aloud in a courtroom.
You will not get your trail to zero. The goal is to cost investigators effort — because effort is the difference between a fishing expedition and a catch.
Keep your head up and your metadata clean. We've survived worse administrations with fewer tools. This site's toolkit runs entirely on your device precisely so it can't be subpoenaed out of my hands — see why everything here is local-first. Stay smart. Stay loud where it's safe. Stay here. <3